CVE-2020-15025

NameCVE-2020-15025
Descriptionntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs963807

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ntp (PTS)stretch1:4.2.8p10+dfsg-3+deb9u2fixed
buster1:4.2.8p12+dfsg-4vulnerable
bullseye, sid1:4.2.8p14+dfsg-2vulnerable
ntpsec (PTS)buster1.1.3+dfsg1-2+deb10u1fixed
bullseye, sid1.1.8+dfsg1-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ntpsourcejessie(not affected)
ntpsourcestretch(not affected)
ntpsource(unstable)(unfixed)low963807
ntpsecsource(unstable)(not affected)

Notes

[buster] - ntp <no-dsa> (Minor issue)
[stretch] - ntp <not-affected> (Vulnerable code introduced later)
[jessie] - ntp <not-affected> (Vulnerable code introduced later)
- ntpsec <not-affected> (Vulnerable code not present)
https://support.ntp.org/bin/view/Main/NtpBug3661
https://support.ntp.org/bin/view/Main/SecurityNotice#June_2020_ntp_4_2_8p15_NTP_Relea
https://bugs.ntp.org/show_bug.cgi?id=3661

Search for package or bug name: Reporting problems